Codename MDASH brings agentic AI cybersecurity to the US government
microsoft.com Sep 8, 2026

Codename MDASH brings agentic AI cybersecurity to the US government

AI-summarised brief · reviewed before publication

Microsoft has deployed Codename MDASH, a multi-model agentic scanning system, to Microsoft Azure Government. This tool provides US government customers and authorized partners with advanced AI capabilities to proactively identify software vulnerabilities. Unlike traditional scanners that rely on known patterns, MDASH uses over 100 specialized AI agents to reason about source code like expert security researchers. The system validates exploitable flaws by analyzing information flow and arguing cases for and against suspected weaknesses. This approach reduces false positives and prioritizes genuine threats. MDASH achieved a 96.55 score on the CyberGym benchmark, demonstrating its effectiveness against real-world vulnerabilities. Its multi-model harness design allows for robust analysis and easy integration of newer AI models without disrupting existing workflows. By focusing on subtle, complex flaws across the software supply chain, Microsoft aims to shift the advantage to defenders against sophisticated cyberattacks targeting critical national missions.

💡 Why It Matters

  • · By replacing static pattern-matching with dynamic, agentic reasoning, this system addresses the critical failure of traditional tools to detect subtle, complex supply chain vulnerabilities.
  • · Its modular harness design ensures agencies can continuously integrate superior AI models without rebuilding their security infrastructure, maintaining long-term defensive resilience.